opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party se
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server du
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
Frequently Asked Questions
What is CWE-506?
CWE-506 (CWE-506) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-506?
There are 71 CVE records associated with CWE-506 in our database. Of these, 19 are critical severity, 45 are high severity, and 1 are medium severity.
How can I protect against CWE-506 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-506 using AI-powered security agents.
Detect CWE-506 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-506 vulnerabilities across your infrastructure.
Get Started